VEM — Virtual Energy Manager

Powered by Claude AI

How can I help?

Ask about energy consumption, ESMs, audit steps, or SEDA requirements

Responses are AI-generated — verify critical figures independently

ATECH.AI·SEMP Platform

Privacy Policy & Data Processing Agreement

Last updated: 3 September 2026  ·  Effective: 5 June 2026 (amended 7 July 2026 and 3 September 2026)

This document governs how Atech Sustainability Consultancy Sdn Bhd (ASC) collects, processes, and protects data submitted to the SEMP platform by client organisations, Registered Energy Auditors (REAs), and Registered Energy Managers (REMs).

Download PDFVersion dated 3 September 2026

2. Our Roles Under the PDPA

The Platform handles two kinds of data, and ASC's role differs for each:

Data controller: platform account data

For the personal data of platform users themselves (names, email addresses, roles, professional registration details, and the records of their activity on the Platform), ASC determines the purposes and means of processing and is the data controller.

Data processor: Client Data

For building, energy, and audit information submitted by or for a client organisation ("Client Data"), including any personal data contained in it such as contact persons or names appearing on utility accounts, the client organisation is the data controller and ASC acts as its data processor. In that capacity ASC processes Client Data only to provide the Platform and on the client's instructions, applies the security measures in Section 8, engages only the sub-processors listed in Section 5 under written data processing terms, assists the client with data subject requests concerning Client Data, notifies the client of personal data breaches as set out in Section 9, and returns or deletes Client Data at the end of the engagement as set out in Section 7.

Client Data may be submitted by the client's own personnel, by ASC staff on the client's behalf, or by a duly appointed REA or REM ("Appointee") acting under professional appointment. Regardless of who uploads it, Client Data is deemed provided by, and remains the responsibility of, the client organisation.

3. Data We Collect

We process two categories of data: Personal Data (relating to identifiable individuals) and Client Data (building and energy information).

CategoryExamplesClassification
User account dataName, preferred name, email address, role, organisation, sign-in timestamps. Passwords are held only by our authentication provider in hashed form.Internal
Professional credentials (REA/REM)Professional registration number, registration type, certificate document, certificate expiry date, and verification statusInternal
Client contact detailsContact person name, designation, email address, and phone number recorded for each client organisation; nominated contact emails for clients using the shared intake folderInternal
Building identity dataBuilding name, address, GFA, occupancy type, stateConfidential
Utility & energy dataTNB bills (account number, kWh, MD, PF, cost), baseline consumption, load profilesClient Confidential
Equipment dataAsset registers, nameplate data, measured kW readingsClient Confidential
Audit outputsESM recommendations, M&V plans, bill verification records, regression analyses, reportsClient Confidential
Raw source filesUploaded PDFs, scanned utility bills, and Excel files, including the original copy of each bill retained as audit evidenceClient Confidential
Support requestsTicket subject, description, comments, and attachments; messages sent through the Support formInternal
AI interaction metadataFeature name, model used, token counts, duration, and status; no prompt or response content is retainedInternal
Security & audit logsActor, action, target, and timestamp of administrative and data actions; security events additionally record IP address, browser user agent, and request pathInternal
Error & diagnostic logsStack traces and request metadata, with cookies, request bodies, and user identifiers removed before transmission (via Sentry)Internal

We do not collect sensitive personal data such as health records, biometric data, government-issued identification numbers, or financial account credentials, and the Platform has no fields for them. You must not upload such data to the Platform.

4. How We Use Your Data

We process data solely for the following purposes:

  • ✓Providing the Platform and its energy audit, ESM recommendation, bill verification, and reporting features
  • ✓Extracting data from uploaded utility bills, spreadsheets, and documents so that it can be reviewed and saved by a user
  • ✓Generating AI-assisted energy saving measure recommendations and draft audit report narratives
  • ✓Calculating energy benchmarks (BEI/EUI) against MS 1525:2019 and SEDA requirements
  • ✓Checking professional registrations at sign-up and monitoring certificate expiry, so that only eligible professionals verify Client Data
  • ✓Running automated data-integrity checks on building records to support the accuracy of Client Data (see 4.1 below)
  • ✓Receiving client documents through the optional shared intake folder, and issuing receipts and reminders for it
  • ✓Sending operational emails: registration verification, approvals, reminders, digests, and support ticket updates
  • ✓Maintaining platform security, including security event logging, performance monitoring, and error diagnostics
  • ✓Responding to and tracking support requests from authorised users
We will not use Client Data to train AI models, sell data to third parties, or include your data in aggregated industry benchmarks without your explicit written consent.

4.1 Automated Processing Transparency

The Platform uses two distinct kinds of automated processing, and we distinguish them deliberately:

Deterministic checks (not AI)

A rules engine (the "Virtual Energy Manager") checks each building's records nightly for data-quality and consistency issues, for example missing utility bills or inconsistent figures. Data-health checks run when bills are entered, and documents received through the shared intake folder are classified by their content using fixed rules. These checks apply fixed, deterministic rules; they do not use AI or machine learning, do not profile individuals, and make no automated decisions about any person. Each finding must be reviewed by a human user: it is either acknowledged or dismissed with a typed reason, which is retained as evidence. This monitoring exists to support the accuracy of Client Data, a core PDPA principle.

AI-assisted features (always subject to human review)

Document parsing suggestions, the chat assistant, draft ESM and report narrative text, and the extraction of registration details from certificates uploaded at sign-up use the AI models listed in Section 5. AI output is always a draft or suggestion: AI never writes directly to Client Data. Saving parsed bill data, approving ESMs, generating reports, and approving a professional's registration are actions taken by a human user. Documents received through the shared intake folder are processed with fixed rules only and are not sent to any AI service.

5. Sub-Processors

ASC engages the following sub-processors. Each is bound by written data processing terms consistent with this Policy. We will give clients at least 14 days' notice of any addition or replacement by updating this page and emailing the client's designated contact.

Sub-ProcessorRoleData TouchedLocation
Supabase, Inc. (USA)Database hosting, user authentication, and file storagePersistent: all Client Data, account data, uploaded files, and logsAWS ap-southeast-1 (Singapore)
Vercel, Inc. (USA)Application hostingRequest routing and session checks on the edge network; application functions handle data in memory for the duration of a request, with no persistent storageFunctions: Singapore (sin1); edge network: location nearest the user
Microsoft Corporation (Microsoft 365)Business email and document collaborationMessages sent through the Support form and system digests received in ASC’s shared mailbox (sender name, email address, message content, file names and statuses); for clients who elect to use the shared intake folder, the documents they place in their own folderMicrosoft 365 data-centre geography assigned to ASC’s Malaysian tenant
Alibaba Cloud (Singapore), Model Studio / DashScope InternationalAI models (Qwen): extraction of data from utility bills, spreadsheets, and documents; extraction of registration details from professional certificates; draft ESM recommendations and draft report narrativesTransient: document images or text extracts sent for inference only; inputs are not used for model training under the provider’s product termsSingapore endpoint
Anthropic, PBC (USA)AI models (Claude): chat assistant, ESM review, Excel bill import, and spreadsheet column mappingTransient: data extracts sent for inference only; not used for model trainingUnited States
Resend, Inc. (USA)Transactional email delivery from noreply@atechsustainability.com: verification, notifications, receipts, and digestsRecipient name, email address, and message content at delivery timeUnited States
Sentry (Functional Software, Inc., USA)Application error monitoringError reports and request metadata, with cookies, request bodies, and user identifiers removed before transmission; 90-day retentionUnited States

Transient processing by AI sub-processors involves transmission of specific data extracts for inference only; the Platform does not instruct those providers to store Client Data, and their handling of in-flight data is governed by their respective API terms. On our own systems, AI calls are logged as metadata only (feature, model, token counts, duration, and status), with no raw prompt or response content retained in those logs.

6. Data Residency & Cross-Border Transfers

All Client Data and account data is stored at rest within AWS ap-southeast-1 (Singapore). Application functions that read or write that data run in Vercel's Singapore region and hold data in memory only for the duration of a request. No persistent storage of Client Data occurs outside Singapore.

The following processing takes place outside Malaysia, each under written data processing terms with the recipient:

  • Singapore: persistent storage, application functions, and Qwen model inference
  • United States: Claude model inference, transactional email delivery, and error diagnostics (identifiers removed)
  • Microsoft 365: email and shared-folder content, in the data-centre geography assigned to ASC's Malaysian tenant

These transfers are made in accordance with section 129 of the PDPA: to jurisdictions whose law provides protection comparable to the PDPA, and with the consent of each user, which is recorded when the user accepts this Policy at registration. ASC does not transfer Client Data to any other jurisdiction without the client's prior written consent.

🌏

Singapore Hosting

AWS ap-southeast-1 is geographically proximate to Malaysia and is subject to Singapore's Personal Data Protection Act 2012, which provides a standard of protection comparable to Malaysia's PDPA.

7. Data Retention & Deletion

Data TypeRetention PeriodBasis
Active Client DataDuration of the client engagement; deleted or anonymised within 30 days of the client’s written request after terminationContractual
Audit reports, ESMs, and verification records7 years after audit completionEECA 2024 record-keeping
Original utility bills and source filesRetained alongside the audit records they evidence, for the same periodEECA 2024 audit evidence
User account dataRemoved when an administrator terminates the account; a professional’s certificate file is deleted at the same timeContractual
Support tickets and attachmentsDuration of the client engagement; removed with Client Data on terminationOperational
Intake staging dataPurged automatically 30 days after a batch is approved or rejectedOperational
Unsaved browser draftsExpire automatically after 14 days, on the user’s own deviceOperational
AI interaction metadataRetained for service monitoring and cost control; contains no prompt or response contentOperational
Security and audit logsMinimum of 12 months, as an accountability and investigation recordPDPA accountability
Error logs (Sentry)90 daysOperational

Upon written request following the end of an engagement, ASC will return, delete, or anonymise Client Data within 30 days and confirm completion in writing, except where:

  • Retention is required by applicable Malaysian law (EECA 2024, PDPA)
  • Data is held in our database provider's backup copies, which are overwritten on the provider's standard rotation
  • Data forms part of aggregated, de-identified platform statistics that cannot be traced back to you

8. Security Measures

ASC implements the following technical and organisational measures, representing our current standard practice. Security measures are updated periodically and do not constitute a guarantee against all possible security incidents.

Need-to-know access, enforced at the database layer

Every energy professional (REA, REM, or energy manager) and every client user can access only the buildings assigned to them by a platform administrator. This building-scoped access control is enforced by database Row Level Security policies at the database layer, not merely in the user interface, and applies equally to dashboards, automated data-integrity insights, support tickets, and the chat assistant's context. Assignments are granted and revoked by platform administrators, and administrator actions are recorded in the audit trail. Cross-client access is limited to ASC staff with a legitimate operational need.

9. Incident Response

ASC maintains a documented personal data breach response procedure, owned by our Data Protection Officer, with defined roles, severity classification, and notification decision steps. Our commitments follow the PDPA breach notification regime introduced by the 2024 Amendment:

  • Where ASC is the data controller (platform account data), ASC will notify the Personal Data Protection Commissioner as soon as practicable and in any event within 72 hours of becoming aware of a personal data breach, and will notify affected individuals without unnecessary delay, and in any event within 7 days, where the breach is likely to cause them significant harm.
  • Where ASC is the data processor (Client Data), ASC will notify the affected client without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting that client's data, so that the client can meet its own obligations as data controller. ASC will cooperate with the client's assessment and any notification the client makes.

Notifications will include:

  • Nature of the breach and the categories of data affected
  • Estimated number of data subjects and records involved
  • Likely consequences
  • Measures taken or proposed to contain and remediate the breach
  • Contact details of our Data Protection Officer
Where the full extent of a breach cannot be established within the initial window, ASC will provide an initial notification with the information available and supplement it as further details are confirmed. Where a breach originates at a sub-processor, ASC's awareness begins when the sub-processor notifies us, and ASC remains responsible for notifying the client.

Incidents arising from the use of a client's or an Appointee's own credentials, or from their own actions, are investigated and handled in cooperation with the client.

10. Your Rights Under the PDPA

Under Malaysia's Personal Data Protection Act 2010, as amended in 2024, you have the following rights with respect to your Personal Data:

→

Right of Access

Request a copy of the Personal Data we hold about you.

→

Right of Correction

Request correction of inaccurate or incomplete Personal Data.

→

Right to Data Portability

Receive the Personal Data you have provided to us in a structured, commonly used, machine-readable format, as introduced by the 2024 Amendment.

→

Right to Withdraw Consent

Withdraw consent for processing at any time, subject to legal or contractual obligations. Withdrawing consent to AI-assisted processing means those features can no longer be used for your uploads.

→

Right to Deletion

Request deletion of your Personal Data, subject to retention obligations under EECA 2024 and the PDPA retention principle (data is not kept longer than necessary).

→

Right to Prevent Processing

Require us to cease processing likely to cause damage or distress, and to cease processing for direct marketing purposes. ASC does not use Platform data for direct marketing.

Requests are handled under a documented procedure. We verify the identity of the requester before acting, and the Platform's audit trail (Section 8) allows us to identify what data we hold about you and how it has been processed. Requests concerning personal data contained in Client Data are referred to the client organisation as data controller, and we assist it in responding.

To exercise any of these rights, contact our Data Protection Officer at kentphang@atechnologies.com.my. We will acknowledge your request on receipt and respond within 21 days.

12. AI Output Disclaimer

Platform Outputs, including ESM recommendations, energy audit narratives, regression analyses, and benchmarks, are provided for informational and decision-support purposes only. They do not constitute professional engineering, legal, or financial advice.

Platform Outputs fall into two categories, and users should understand the distinction:

  • AI-generated content: document parsing suggestions, chat assistant responses, and draft ESM and report narrative text. These are drafts and suggestions only, are always subject to human verification before being saved or relied upon, and chat responses carry an in-product disclaimer. AI never writes directly to Client Data.
  • Deterministic outputs: benchmark calculations (BEI/EUI), regression analyses, and data-integrity findings from the rules engine described in Section 4.1. These are produced by fixed formulas and rules, not AI models.

For transparency: our systems log AI usage as metadata only (feature, model, token counts, duration, and status). Raw prompt and response content is not retained in those logs.

The professional responsibility for all energy audit conclusions, certifications, and submissions to SEDA Malaysia or any regulatory authority rests solely with the appointed REA or REM and the client organisation. ASC accepts no liability for decisions made in reliance on Platform Outputs without independent professional verification.

© 2026 Atech Sustainability Consultancy Sdn Bhd (ASC). All rights reserved.  ·  SEMP (Sustainable Energy Management Program)  ·  Governed by Malaysian law